
Security Engineer, Platform
Posted Jul 16

Posted Jul 16
This is a fully remote position, open to applicants in United States.
• Develop and enhance the security framework of Resend’s platform, encompassing API keys, service permissions, secrets management, tenant isolation, audit logs, and internal access controls.
• Assist in designing secure defaults for new services, workers, queues, databases, internal tools, and deployment pipelines.
• Enhance detection and response mechanisms for suspicious access, credential leaks, abnormal sending patterns, privilege modifications, and critical system events.
• Evaluate and refine our processes and pipelines to ensure that security is inherently integrated rather than added on later.
• Elevate the overall security standards.
• Possess experience in securing production infrastructure, cloud environments, APIs, developer platforms, or multi-tenant SaaS applications.
• Proficient in coding and comfortable with reading application, infrastructure, and deployment code.
• Have a solid understanding of authentication, authorization, secrets management, IAM, logging, audit trails, incident response, and secure deployment pipelines.
• Be capable of independently prioritizing and managing daily tasks as the first dedicated security hire.
• Favor practical enhancements over cumbersome processes.
• Exhibit low-ego, direct communication, curiosity, and a willingness to learn from others.
• Value developer experience and advocate for security that is easy to implement.
• Have experience with email infrastructure, transactional email, sender reputation, domain verification, SPF, DKIM, DMARC, webhooks, or abuse prevention.
• Have secured cloud infrastructure utilizing tools such as AWS, Terraform, Kubernetes, Cloudflare, or comparable systems.
• Have a background in open-source security, GitHub organization hardening, package publishing, dependency evaluation, or supply-chain security.
• Have assisted a company in preparing for SOC 2, ISO 27001, GDPR, enterprise security evaluations, or customer trust processes without transforming engineering into a compliance-driven entity.
• Have developed security observability, alerting, detection pipelines, or incident response workflows.
• Have collaborated closely with Trust & Safety, anti-abuse, fraud, or platform integrity teams.
• Possess experience in designing security systems for high-scale developer products.
• 100% remote team with flexible working hours.
• Modern technology stack (Next.js, Raycast, Notion, etc.).
• An honest and low-ego team environment.
• Ownership of problems and solutions.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.